External risk intelligence

Click5 CRM Add-on for Contact Form 7 Unauthenticated Site Takeover via Option Update

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84254

This vulnerability affects a WordPress plugin which, by definition, is designed to be deployed as a public-facing web application. Since the issue exists within a REST endpoint used by the plugin, it is reachable via the public internet as part of the standard web application surface.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in a WordPress plugin that, if exploited, could allow attackers to gain full control of a website by changing critical settings. This issue stems from a lack of proper security checks within the plugin's update mechanism, potentially enabling unauthorized modifications to website options. The main concern at this time is to confirm if this specific plugin is in use and exposed.

  • Unchecked updates can let anyone alter site settings.
  • Website takeover is possible via this plugin flaw.
  • Confirm usage to understand potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit a vulnerability in a WordPress plugin's REST endpoint to alter arbitrary blog settings. This could allow an attacker to create a new administrator account and gain full control over the website.

  • No authentication required.
  • Update options via REST endpoint.
  • Full site takeover possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in a WordPress plugin could allow an unauthenticated attacker to alter any blog setting when supported by the advisory. This means an attacker could potentially create a new administrator account, leading to a complete takeover of the website and its hosted content.

  • Arbitrary blog options could be modified.
  • Unauthenticated attackers can reach a REST endpoint.
  • Website takeover, including new admin creation.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a WordPress plugin's REST endpoint indicates that platform or web application teams are likely responsible for remediation. The first step is to identify all instances of the affected plugin, determine their reachability and business criticality, and then assign ownership for addressing the risk.

  • Platform and application owners should investigate.
  • Verify plugin instances and their exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the click5 CRM add-on for Contact Form 7?

It is a WordPress plugin extension designed to integrate Contact Form 7 submissions directly into a CRM system. Users rely on it to automate data collection and manage customer interactions. Because it connects external data streams to a WordPress site, it includes functional REST endpoints that allow the software to communicate with outside services.

What does CWE-862 mean for CVE-2026-84254?

CWE-862 is the classification for 'Missing Authorization.' In the context of this CVE, it means the plugin's REST endpoint fails to verify if the person requesting an action has permission to perform it. It also lacks a Cross-Site Request Forgery (CSRF) check, essentially leaving a door unlocked that allows anyone to send instructions to the plugin as if they were a site administrator.

How do attackers trigger this vulnerability?

An attacker targets the plugin’s REST endpoint by sending a crafted request that updates site settings. The bug is triggered because the software does not restrict which options can be changed, nor does it check if the request is legitimate. It is important to note that this requires no prior login or special access to the site; simply reaching the public endpoint is sufficient to initiate the unauthorized change.

Why is this a concern if my site is on the public internet?

According to Halo Surface Signal, this plugin is inherently designed to be public-facing, meaning the vulnerable REST endpoint is reachable via the open internet. Because it does not require authentication, any remote attacker can attempt to interact with the plugin. This makes the risk higher for standard WordPress installations that are accessible to the public.

What should I do if I use this plugin?

First, audit your WordPress environment to confirm if the click5 CRM add-on is installed and active. Since this vulnerability allows an attacker to create new administrator accounts, review your current user list for any unrecognized accounts. Prioritize identifying where this plugin is running on your network and work with your application team to restrict access or remove the plugin until a secure update is available.

References